Windows 10 Creators Update - Security Breach Found (or feature...)

Page 1 of 2 12 LastLast

  1. Posts : 7
    Windows 10
       #1

    Windows 10 Creators Update - Security Breach Found (or feature...)


    Call this a feature if you want, but it's a terrible one..

    Things you'll need setup to reproduce the issue:
    • Windows 10, Version 1703, OS Build - 15063.296
    • A PIN/Password code login
    • Display timeout of 1 minute

    By pressing the Windows Key, search 'power plan' and select Edit Power Plan.Set 'Turn off the display' after 1 minute.
    How to replicate the issue:

    Firstly, lock your PC with CTRL + L on your keyboard to confirm that when you slide the lockscreen up, it prompts you to enter a PIN/Password.

    If that works fine, then try to do this step and replicate the issue I'm having.

    Let your PC lock after 1min, don't touch anything.

    If it blacks out, wake the screen but stay on the lockscreen.

    Now, slide the lockscreen up by pressing any key and it should promp-..... it's probably taken you straight into the computer without asking for any PIN/Passcode.

    Solution:
    Call up Microsoft/live chat to Microsoft and allow them to Remote Desktop into your PC only to make them realize that they can't do anything. They kept telling me the update wasn't the issue and to roll back..

    It's happened on my Home PC and now my recently updated Work PC. So it's not a coincidence, this is ridiculous and Microsoft should know better.

    All in all, there is no solution. Stay on the Anniversary Update or previous builds.

    Let me know your results.

    (glad to be a part of the community)

    ###############UPDATE##################

    Solution provided by Edwin

    "You'll need to use Screen Saver settings to enable that security feature."

    Last edited by AsadP; 23 May 2017 at 05:54.
      My Computer


  2. Posts : 42,983
    Win 10 Pro (22H2) (2nd PC is 22H2)
       #2

    Turning the display off isn't the same as locking your PC.

    Consider a desktop.. say you switch the monitor off, then switch it back on again. Would you expect to have to log in?

    (I don't use a PIN though so can't compare- but I do use the AU).
      My Computers


  3. Posts : 7
    Windows 10
    Thread Starter
       #3

    dalchina said:
    Turning the display off isn't the same as locking your PC.

    Consider a desktop.. say you switch the monitor off, then switch it back on again. Would you expect to have to log in?

    (I don't use a PIN though so can't compare- but I do use the AU).
    Of course turning the display off isn't the same as locking but what if you forget to lock your device and want the PC to lock after the display turns off?

    This used to work perfectly fine in the previous builds as mentioned, namely the Anniversary Update.

    Thanks for your input.
      My Computer


  4. Posts : 4,201
    Windows 10 Pro x64 Latest RP
       #4

    There has always been a delay in the requirement for a password, (or now pin), entry in windows after the Screen timeout activates. it's there to allow users to return to their work if the timeout occurs at an inconvenient time, This often happens in business when a user is reviewing a document, and has the timeout set to a low number and the require Password on wakeup is set.

    It used to be 30 secs IIRC but I could be wrong as my memory is no longer foolproof. (I still know all the stuff I used to but there's lots of junk stacked on top of it )

    Incidentally there is also a delay built into the wake-up of a system in sleep or hibernation, which can be caused by a mouse vibration, if no activity occurs in a set time, (3 Mins?), the system will go back to sleep /hibernation - This delay did have an entry in the registry so could be adjusted on systems that are prone to this issue but not sure if there is a similar option for the password requirement delay
      My Computers


  5. Posts : 7
    Windows 10
    Thread Starter
       #5

    Barman58 said:
    There has always been a delay in the requirement for a password, (or now pin), entry in windows after the Screen timeout activates. it's there to allow users to return to their work if the timeout occurs at an inconvenient time, This often happens in business when a user is reviewing a document, and has the timeout set to a low number and the require Password on wakeup is set.

    It used to be 30 secs IIRC but I could be wrong as my memory is no longer foolproof. (I still know all the stuff I used to but there's lots of junk stacked on top of it )

    Incidentally there is also a delay built into the wake-up of a system in sleep or hibernation, which can be caused by a mouse vibration, if no activity occurs in a set time, (3 Mins?), the system will go back to sleep /hibernation - This delay did have an entry in the registry so could be adjusted on systems that are prone to this issue but not sure if there is a similar option for the password requirement delay
    See this explains it.

    But where the hell is that setting gone in this update and why does it seem like that setting has been wiped indefinitely so there is no timeout anymore..
      My Computer


  6. Posts : 18,432
    Windows 11 Pro
       #6

    AsadP said:
    See this explains it.

    But where the hell is that setting gone in this update and why does it seem like that setting has been wiped indefinitely so there is no timeout anymore..
    It's under settings, system, power & sleep. Adjust the sleep timeout to match the screen turn off time.

    Under settings, accounts, sign in options is the option to require the computer to ask for a password when waking from sleep. There is no option to ask for password when only turning the screen back on after the it has turned off.
      My Computer


  7. Posts : 17,838
    Windows 10
       #7

    AsadP said:
    See this explains it.

    But where the hell is that setting gone in this update and why does it seem like that setting has been wiped indefinitely so there is no timeout anymore..
    You'll need to use Screen Saver settings to enable that security feature.

    Windows 10 Creators Update - Security Breach Found (or feature...)-000133.png
      My Computer


  8. Posts : 42,983
    Win 10 Pro (22H2) (2nd PC is 22H2)
       #8

    Just beat me to it Edwin!!
      My Computers


  9. Posts : 17,838
    Windows 10
       #9

    dalchina said:
    Just beat me to it Edwin!!
    A collaborative effort!
      My Computer


  10. Posts : 4,201
    Windows 10 Pro x64 Latest RP
       #10

    Maybe this needs to be read , I've not checked if the key actually exists in the latest release , and if so what the default is but at least I've remembered "Grace Period"

    Change Screen Saver Password Grace Period in Windows Windows 10 General Tips Tutorials
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 16:09.
Find Us




Windows 10 Forums